Protection by device: five platforms, five different answers
A single subscription covering "all your devices" implies the devices have the same problem. They do not. The threat model, the protection already present and the room a third-party product has to operate differ so much between a Windows desktop and an iPhone that they are better treated as five separate decisions that happen to be billed together.
| Platform | Protection model | What third-party software typically adds | Principal limit |
|---|---|---|---|
| Windows | Built-in real-time anti-malware maintained by the platform vendor, enabled by default | Alternative engine, central management across devices, extra filtering layers | The largest volume of malware targets this platform |
| macOS | Layered controls: code signing, application vetting, and platform-maintained malware removal | Broader scanning, cross-platform management, detection of threats aimed at other systems | Smaller but real and growing malware volume |
| Linux desktop | Package-manager distribution and strict permission separation; few consumer products available | On-demand scanning, often used to find malware aimed at other platforms in shared files | Consumer tooling is sparse; server products dominate |
| Android | Application sandboxing plus store-level scanning of installed applications | Scanning of sideloaded packages, link filtering, lost-device tools | Risk concentrates in applications installed from outside the official store |
| iOS and iPadOS | Strict sandboxing; applications cannot inspect other applications or system files | Web and link filtering, breach notifications — not file scanning, which the platform does not permit | An "antivirus" app cannot scan the device in the way the name suggests |
Windows
Windows remains the platform most malware is written for, simply because of how many machines run it. Current versions include real-time anti-malware from the platform vendor, switched on by default and updated through the ordinary update channel, so a Windows computer that is patched and left alone is not unprotected.
What a third-party product can add is genuine but specific: a second detection engine with different data behind it, management of several machines from one place, more aggressive filtering of web addresses, and controls over removable media. Two details are worth knowing. Installing a third-party real-time product generally causes the built-in protection to step aside, so you are replacing a layer rather than stacking two — running two real-time engines at once causes conflicts rather than doubling protection. And when a third-party subscription lapses, the built-in protection normally resumes, but it is worth confirming rather than assuming.
- Confirm real-time protection is on and definitions are current.
- Confirm Windows Update is applying updates automatically.
- Check that a previous trial has not left protection switched off.
- Use a standard account rather than an administrator account for everyday work.
- Keep a backup that is not permanently connected to the machine.
macOS
Apple's model relies less on scanning and more on preventing unvetted code from running at all: applications are signed, applications from the company's store are reviewed, and the system carries its own facility for identifying and removing known malicious software. The claim that Macs cannot be infected has not been accurate for years, but the volume and the delivery routes differ from Windows.
Most successful attacks on Mac users come through installers presented as something legitimate — a codec, a player update, a "cleaner" — and through browser-based deception rather than through exploits of the system itself. Third-party software helps by catching those installers earlier and by identifying files that are harmless on a Mac but dangerous when passed on to a Windows machine. Anything advertised as a Mac performance cleaner deserves suspicion; that category has a poor history.
Linux on the desktop
Desktop Linux occupies an unusual position. Software normally arrives through a distribution's package manager, which is a verified channel, and the permission model makes it awkward for a program to affect the whole system without explicit escalation. Consumer antivirus products for Linux desktops are correspondingly rare, and most security tooling for Linux is built for servers.
The common reason a Linux desktop user runs a scanner is not self-protection but hygiene: checking files that will be passed to Windows or macOS users, and scanning shared storage. Where a product lists Linux support, it is worth checking which distributions and which release versions are actually covered, since support lists in this area are narrower than the word "Linux" suggests.
Android
Android isolates applications from each other, and the official store scans what it distributes. The practical risk sits outside that: applications installed from outside the store, applications that request permissions far beyond their function, and messages that lead to a credential-harvesting page rather than to malware.
A security application can inspect packages installed from outside the store, warn about excessive permissions, filter links, and help locate a lost handset. It cannot undo a permission you granted deliberately. A periodic review of which applications hold access to messages, accessibility services and device administration is worth more than most features in the category.
- Which applications hold accessibility or device-administration permissions.
- Whether installation from unknown sources is enabled for any application.
- Whether the operating system is still receiving security updates from the manufacturer.
- Whether screen lock and multi-factor authentication are enabled on the account tied to the device.
iOS and iPadOS
This is where the category's vocabulary breaks down. On iPhone and iPad, an application cannot read another application's files or inspect the operating system, and that restriction applies to security applications as much as to anything else. An "antivirus" application on iOS therefore does not scan the device for viruses, because the platform does not allow it to.
What such applications do provide is real but different: filtering of web addresses through the system's content-blocking mechanism, warnings about credentials exposed in known breaches, and safety tools for a lost device. Those are worth having if you want them; they are not file scanning, and a product implying otherwise is describing something the platform does not permit.
Tablets and shared family devices
A tablet used by several people in a household inherits the habits of all of them. Separate user profiles where the platform supports them, parental controls where they are appropriate, and an explicit rule about who may install software do more than any subscription. The eSafety Commissioner publishes Australian guidance on family device use and online safety, and it is written for parents rather than for administrators.
Matching a subscription to a mixed household
Most Australian households run at least three of these five platforms. Two questions decide whether a single subscription is the right answer: does the plan cover every operating system on your list, and does its device limit cover the number of installations you need. A plan that misses one platform leaves you managing two arrangements, which is usually worse than managing one consciously.
Surfshark Antivirus, the product this site has a commercial relationship with, states support for desktop computers running Windows, macOS and Linux, mobile devices running Android, iOS and Windows, and tablets running iOS, Android and Windows. The device limit for any given plan is published by the vendor rather than here.
The following is a paid affiliate link: a subscription purchased through it pays MSMM-SOU s.r.o. a commission from the vendor, with no change to your price. Platform support and plan limits should be confirmed on the vendor's own pages.
The step that applies to every platform
Whichever devices are on your list, the measure with the widest effect is the same: keep the operating system and the applications updated, and retire anything the manufacturer no longer supports with security updates. Malware overwhelmingly arrives through flaws that already have fixes available. The Australian Cyber Security Centre publishes current, free guidance on updates and device hardening for individuals and small businesses, and it applies regardless of what you buy.